Director of Cybersecurity & Resilience

Charlesbridge Group

Weymouth (MA)

On-site

USD 167,000 - 200,000

Full time

5 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Competitive benefits

Job summary

Charlesbridge in Weymouth, MA (and Dedham) seeks a senior cybersecurity leader to shape and drive the organization’s security program. You will own strategy, risk management, and incident response, collaborating with privacy, compliance, and business units to protect data and enable risk-aware growth.

You will establish governance frameworks, manage cybersecurity budgets, and oversee operations, IAM, and vendor risk while communicating with executives about risk and resilience.

Qualifications

  • Bachelor's degree in cybersecurity, information systems, computer science, risk management, or related field.
  • 10+ years in cybersecurity, information security, or IT risk with leadership in a regulated environment.
  • 5+ years in financial services experience; knowledge of banking products and regulatory concepts.
  • Experience with governance, risk assessments, security operations, vulnerability management, incident response, IAM, third-party risk, data protection, and cyber resilience.
  • Proven leadership of employees and cybersecurity service providers.

Responsibilities

  • Develop, maintain, and execute cybersecurity strategy, policies, standards, and roadmap aligned with objectives and risk appetite.
  • Oversee CyberOps including monitoring, detection, investigation, escalation, and secure configuration of platforms.
  • Lead IT and cybersecurity risk management, maintain risk registers, and elevate exposures beyond thresholds.
  • Coordinate third‑party risk management, audits, and regulatory examinations.
  • Coordinate incident response planning, testing, and lessons learned; manage risk reporting to senior management.

Skills

Banking knowledge
Communication skills
Typing skills
Math skills
Willingness to learn

Education

Bachelor's degree in cybersecurity / information systems / risk management
10+ years cybersecurity / IT risk experience
5+ years in financial services
Leadership of cybersecurity teams
Certifications (CISSP / CISM / CRISC) preferred

Job description

Charlesbridge - Dedham or Weymouth, MA • Information Technology

ESSENTIAL DUTIES AND RESPONSIBILITIES
  • Accountable for developing, maintaining, and executing the organization's cybersecurity strategy, program, policies, standards, and roadmap in alignment with organizational objectives, risk appetite, applicable laws and regulations, and recognized frameworks such as the NIST Cybersecurity Framework, NIST 800-53, ISO 27001/2, and other financial industry guidance, where applicable.
  • Accountable for the effective delivery of Cybersecurity Operations (CyberOps), including security monitoring, detection, investigation, escalation, containment, recovery, and the secure configuration, hardening, testing, deployment, and maintenance of cybersecurity technology platforms.
  • Lead the IT and cybersecurity risk management process, including risk identification, assessment, treatment, acceptance, monitoring, and reporting. Maintain current risk assessments and risk registers, establish action plans, and elevate exposures that exceed approved risk thresholds.
  • Maintain a risk-based vulnerability and threat management program covering internal and external scanning, penetration testing, configuration weaknesses, threat intelligence, remediation validation, exception management, and timely escalation of overdue or high-risk findings.
  • Serve as a leader of the organization's incident response team for cybersecurity events and suspected breaches of confidential information. Maintain and test cybersecurity incident response plans, playbooks, communication protocols, evidence-handling practices, and escalation procedures; coordinate lessons learned and corrective actions.
  • Oversee cybersecurity requirements for identity and access management, including privileged access, multifactor authentication, periodic access reviews, segregation of duties, joiner-mover-leaver controls, service accounts, and timely remediation of inappropriate access.
  • Establish cybersecurity architecture, secure configuration, and system hardening requirements. Identify and measure cybersecurity and IT risk before material technology changes, new products, system implementations, cloud adoption, integrations, or significant investments are approved or deployed.
  • Accountable for managing and maintaining the third-party risk management lifecycle, including due diligence, risk assessment, control evaluation, contractual security requirements, ongoing monitoring, issue management, incident coordination, and termination or transition risk.
  • Accountable for managing and maintaining the business continuity management function including technology resilience, business continuity, disaster recovery, backup security, and recovery testing. Ensure cyber scenarios, including destructive attacks and prolonged technology outages, are incorporated into exercises and remediation plans.
  • Oversee technical and administrative safeguards for sensitive and non-public information, including encryption, data loss prevention, secure transmission, logging, monitoring, and other information protection controls. Coordinate security requirements with privacy, legal, compliance, and business stakeholders.
  • Analyze and monitor cybersecurity and IT risk metrics, key risk indicators, key performance indicators, control effectiveness measures, incidents, vulnerabilities, exceptions, and remediation status. Identify trends and provide clear, decision-useful reporting to Senior Management and appropriate governance committees.
  • Coordinate cybersecurity and IT risk support for internal audits, external audits, regulatory examinations, independent assessments, penetration tests, and control reviews. Recommend and initiate corrective actions, track findings to validated closure, and maintain supporting evidence.
  • Assist in the coordination of the cybersecurity awareness and education program, including role-based training, phishing education and testing, targeted communications, and reporting. Promote prompt reporting of suspicious activity and reinforce employee responsibilities for safeguarding information.
  • Maintain accurate and current cybersecurity and IT risk policies, standards, procedures, control documentation, diagrams, inventories, risk records, exceptions, testing evidence, and management reports.
  • Develop and manage the cybersecurity budget, resource plan, and investment priorities based on risk, regulatory expectations, control effectiveness, technology lifecycle considerations, and the cybersecurity strategy.
  • Participate on the organization's Technology Committee and other governance committees as required. Present material cybersecurity and IT risks, incidents, control gaps, investment needs, and remediation progress in clear business terms.
  • Provide supervision and support to assigned cybersecurity personnel and oversee cybersecurity service providers. Establish responsibilities, performance expectations, escalation requirements, cross-training, succession coverage, and accountability for deliverables.
  • Maintain awareness of changes in cyber threats, attack techniques, regulatory expectations, and security practices. Recommend proportionate improvements to cybersecurity controls, processes, staffing, and technologies based on risk and lessons learned.
  • Complete all internal Company training as assigned and required.
  • Adhere to the Company’s privacy and data security policies including but not limited to safeguarding of sensitive information and complying with relevant regulations to protect non-public information.
  • Exhibit the ability and desire to embrace and enhance the Company culture.

Consider this description to be the foundation of your job, not its boundaries. Expect to participate in internal and external training sessions and activities not described here which enhance the quality of service to the client.

SUPERVISORY RESPONSIBILITIES

Directly manages assigned employees in the Cybersecurity and Business Resilience functions and oversees cybersecurity and business resilience service providers. Carries out supervisory responsibilities in accordance with the organization's policies and applicable laws. Responsibilities include interviewing, hiring, and training employees; planning, assigning, and directing work; appraising performance; rewarding and disciplining employees; addressing complaints; and resolving problems.

Requirements
QUALIFICATIONS

To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

EDUCATION and/or EXPERIENCE
  • Bachelor's Degree from a four-year college or university in cybersecurity, information systems, computer science, risk management, or a related field, or an equivalent combination of education and directly relevant experience.
  • Ten or more years of progressively responsible cybersecurity, information security, or IT risk experience, including experience leading cybersecurity functions in a complex, regulated environment.
  • Five or more years of financial services experience and knowledge of banking products, cybersecurity risks, regulatory expectations, and terminology preferred, but not required.
  • Demonstrated experience with cybersecurity governance, risk assessments, security operations, vulnerability management, incident response, identity and access management, third-party cybersecurity risk, data protection, and cyber resilience.
  • Proven successful experience as a leader of employees and cybersecurity service providers, with the ability to establish accountability and produce results.
  • Experience developing cybersecurity budgets, resource plans, metrics, and risk-based investment priorities.
  • Ability to communicate cybersecurity and IT risk matters effectively to technical teams, business leaders, Senior Management, auditors, examiners, and governance committees.
  • Strong analytical, organizational, planning, problem-solving, influencing, and change management skills.
  • Relevant professional certification, such as CISSP, CISM, CRISC, or equivalent, preferred.
  • Competent level of proficiency with Microsoft Office and cybersecurity, risk management, reporting, and productivity tools necessary to perform the role.
SKILLS
  • Basic knowledge of the banking and financial services industry including federal laws and regulations
  • Willingness to gain new knowledge and technical skills.
  • Intermediate typing skills to meet the production needs of the position.
  • Intermediate math skills: the ability to calculate interest, commissions, proportions, and percentages; balance accounts; add, subtract, multiply, and divide into all units of measure, using whole numbers, common fractions, and decimals; locate routine mathematical errors; compute rate, ratio, and percent, including the drafting and interpretation of bar graphs.
  • Exceptional verbal, written, and interpersonal communication skills with the ability to apply common sense to carry out instructions and instruct others, train personnel, read, analyze, and interpret documents and professional journals, understand procedures, write reports, correspondence, and procedures, speak clearly to customers and employees.
ADDITIONAL JOB REQUIREMENTS / ADA CONSIDERATIONS

The employee must be able to communicate effectively with internal and external stakeholders, including but not limited to, clients, prospects, employees, management, and external partners in person, by phone, virtually, and in writing; read, interpret, and prepare business, banking, regulatory, proposal, contract, and client documentation as applicable to the role; and apply business- and financial-related concepts, analysis, or calculations as appropriate to the role. Work is primarily performed in a professional office environment and may include client locations, meetings, presentations, conferences, association events, and other business development settings. The role requires regular use of a computer, phone, virtual meeting tools, and standard office technology; the ability to review screens and documents; occasional travel within the market area; and occasional lifting or moving of materials up to 10 pounds. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions, consistent with applicable law.

KEY POINTS

For those seeking to deliver the latest financial solutions rooted in trustworthy, high-quality service, Charlesbridge, a mutual bank holding company, provides operational support, resources, legacy, and innovative thinking to financial institutions so they can deliver a suite of flexible, personalized solutions designed to meet the evolving needs of our clients and our communities. Our local roots, dedication to the communities we serve, loyalty to our people, and commitment to excellence ensure that we remain a trusted partner in an ever-evolving financial journey, today and tomorrow. While our employees are committed to helping our clients, we are committed to our employees. To support our employees, we offer a competitive benefit package with Medical, Dental, Vision, Flexible Spending, Tuition Reimbursement, Childcare Subsidy, Retirement, Life Insurance, and many other benefits.

Charlesbridge is committed to providing equal opportunity for all employees and applicants without regard to race, color, religion, gender, sexual orientation, age, marital status, national origin, physical or mental disability, veteran or disability status, gender identity, or expression, citizenship, genetic information, ancestral origin, military status, pregnancy, childbirth, and or conditions relating to pregnancy or any other related medical conditions or any other status protected by Federal, State or local laws.

Here at Charlesbridge, we strive to foster a culture where every voice is valued and where employees have a sense of belonging and connection with each other. We are dedicated to creating a work environment that understands, supports, and welcomes diverse perspectives and backgrounds. Together, we will create an inclusive and culturally competent and supportive environment where employees model behavior that enriches both Banks and the communities we support.

PAY RANGE DISCLOSURE

The pay range for this position is $166,500 to $199,800 per year and is the lowest to highest salary Charlesbridge in good faith believe we would pay for this role at the time of this posting. The Company may ultimately pay more or less than the posted range, and the range may be modified in the future. An employee’s pay position within the salary range will be based on several factors including, but not limited to, relevant education, qualifications, certifications, experience, sales or revenue-based metrics, and business or organizational needs and affordability.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Director of Cybersecurity & Resilience
Director of Cybersecurity & Resilience

South Shore Bank • Dedham (MA)

On-site
USD 167,000 - 200,000
Facilities Technician
Facilities Technician

Dedham Savings • Dedham (MA), Northern (KY)

Hybrid
USD 34,000 - 42,000
Facilities Technician
Facilities Technician

South Shore Bank • Dedham (MA)

On-site
USD 52,000 - 63,000
Associate Security Operations Engineer
Associate Security Operations Engineer

Conference of State Bank Supervisors (CSBS) • Washington

Hybrid
USD 70,000 - 110,000
Comprehensive benefits
Hybrid work environment
Director Cybersecurity Operational Risk Oversight
Director Cybersecurity Operational Risk Oversight

Citizens • Johnston (RI)

On-site
USD 178,000 - 220,000
Senior Associate/Cybersecurity Consultant Due Diligence Advisory (Forensic Services practice)
Senior Associate/Cybersecurity Consultant Due Diligence Advisory (Forensic Services practice)

Charles River Associates • Boston (MA)

Hybrid
USD 130,000 - 153,000
Medical, dental, vision insurance
401(k) with employer match
Paid time off
Account Associate - State Farm Agent Team Member
Account Associate - State Farm Agent Team Member

Carla Fenzel - State Farm Agent • Jacksonville (FL)

On-site
USD 140,000 - 165,000
Health and Wellness benefits
401(k) and retirement planning
Employee Assistance Program
+3
Senior Associate/Cybersecurity Consultant Due Diligence Advisory (Forensic Services practice)
Senior Associate/Cybersecurity Consultant Due Diligence Advisory (Forensic Services practice)

Charles River Associates • United States

Hybrid
USD 130,000 - 153,000
Cyber Defense Incident Response Lead
Cyber Defense Incident Response Lead

KeyBank • Brooklyn (OH)

On-site
USD 96,000 - 181,000
Senior Associate/Cybersecurity Consultant Due Diligence Advisory (Forensic Services practice)
Senior Associate/Cybersecurity Consultant Due Diligence Advisory (Forensic Services practice)

Charles River Associates • Washington

Hybrid
USD 130,000 - 153,000
Wellness programs
Commuter benefits